skip to main content

Episode 62

Internet of Things devices such as smart televisions and thermostats often lack adequate built-in security, leading to privacy and safety risks not commonly understood by consumers. John Blythe, PhD, argues that a labelling scheme for these devices will provide consumers with a clear picture of the security of an IoT device and help them to choose technology that meets their security and privacy needs.

About the expert: John Blythe, PhD

John Blythe, PhD Dr. John Blythe is a research associate at the Dawes Center for Future Crime at University College London where he works on the consumer security index part of the PETRAS Internet of Things Research Hub. The PETRAS Internet of Things Research Hub is a consortium of nine leading United Kingdom universities that are working together over three years to explore critical issues in privacy, ethics, trust, reliability, acceptability and security. Dr. Blythe previously held positions at the UCL Center for Behavior Change and the Department for Digital Culture, Media, and Sport and PaCT Lab at Northumbria University. His research focuses on exploring behavior change and cyber security.

Transcript

Kim Mills: Hello and welcome to Speaking of Psychology, a podcast produced by the American Psychological Association. I'm your host, Kim Mills. Speaking of Psychology is a podcast for anyone with an interest in the science of psychology. We talk to psychological researchers, practitioners and educators about any and every aspect of psychology and its application to the world around us. Dr. John Blythe is a research associate at the Dawes Center for Future Crime at University College London where he works on the consumer security index part of the PETRAS Internet of Things Research Hub. The PETRAS Internet of Things Research Hub is a consortium of nine leading United Kingdom universities that are working together over three years to explore critical issues in privacy, ethics, trust, reliability, acceptability and security. Dr. Blythe previously held positions at the UCL Center for Behavior Change and the Department for Digital Culture, Media, and Sport and PaCT Lab at Northumbria University. His research focuses on exploring behavior change and cyber security. Thank you for joining us, Dr. Blythe.

John Blythe: Thank you for having us.

Kim Mills: So the Center for Future Crime—that's kind of an intriguing name. What does that mean to study future crime?

John Blythe: So at the Center for Future Crime, we seek to focus essentially on horizon scan—what the crimes are that may arise from technological change or societal changes of the future? We also try to design out these risks through policy and regulation.

Kim Mills: So your research looks at security issues around the ‘Internet of Things.’ Could you explain for people what the Internet of Things is?

John Blythe: Certainly. So, the Internet of Things is essentially everyday objects with the ability to connect to and exchange data over the internet and includes many different objects from Fitbits to Amazon Alexas, smartwatches, all the way up to connected dishwashers, connected thermostats. And it's essentially the ability to use these products via the internet and it gives us many different affordances. Such as in the case of thermostats, it would be personalized heating services based on our behavior and habits.

Kim Mills: Why should we be concerned about the security around the Internet of Things?

John Blythe: These devices are in our homes. They may be connected to a boiler. They may be connected to a critical function in our house such as a smoke alarm and if these are interconnected, it means that a hacker can potentially exploit that device. So, you think about the boiler example. It could be hacked, and the fire could be caused that could potentially lead to loss of life. So, it's no longer just thinking about security in the privacy of our personal data, but it's also well-being and potential life as well that can be exploited by these inherently insecure devices.

Kim Mills: And so what can be done to make them more secure?

John Blythe: So at the minute, manufacturers simply aren't given enough consideration to the security of IOT. They are shipping these products out with essentially market failures. An example of some of these market failures is that a lot of these problems can't be updated, so a vulnerability may be found in a product, but a large portion population may already purchase that product and there’s nothing that the consumer can do about that. They now have a product that can't be updated anymore. And that's an example of one of the market failures. What we call it in chrome studies is a ‘crime harvest’ which is where an innovation is introduced into society and there’s not given adequate consequences of the crime. So the same thing happened when we started using vehicles. Vehicles were designed, but they weren't designed with crime in mind. So what happens is that the criminals will start to leave the crime hops. They recognize the potential opportunities that can be afforded by the lack of security of the innovation, and then what then happens is that we recognize the potential crime consequences and then try to design out that crime.

Kim Mills: And what incentives do manufacturers have to make these products more secure at this point?

John Blythe: At this point there’s very little incentive for manufacturers to take this seriously, which is why we're not really seeing manufacturers actually ship these products with security in-built, or in the UK we call it security by design, making sure the security’s baked into the products before you ship it out to consumers. What manufacturers are doing is to put all the burden on the consumer-especially the consumer to protect the device, to change lots of passwords, to change all the settings to essentially make the consumer protect the product rather than them shipping it and with better security in the first place.

Kim Mills: I understand that some of the research you've done is around labeling. Can you talk about what that means? How should these products be labeled?

John Blythe: So the labeling scheme, which is called a “consumer security index” in our project, it's part of the UK government's initiative to improve the security of these products. So March this year, the UK government, specifically the Department for Digital Culture, Media & Sport are in charge of this security policy announced their secured-by-design for consumer IOT report which outlined the government measures for improving the security of these devices. Primarily, this was a court of practice that manufacturers should follow to ensure these products are secured-by-design, but a supplementary measure was to explore the role of the labeling scheme to first get consumer choice because if the minute you were to go and buy a smart device for example a smart kettle from a store, there's no way for you to make a distinction between a secure product and insecure product. So, the label would help you make that choice in that decision. The second intention of the label is to actually incentivize manufacturers to actually ship these products for security in the first place. Otherwise, they potentially risk reputational damage.

Kim Mills: Do consumers have any idea at this point how insecure these products are?

John Blythe: So, a lot of research lately has suggested that the main barrier to adoption of The Net of Things is security and privacy concerns. We know that people are concerned about how they did and may be used from these products and how that may be shared with third-party companies, but people aren't readily protecting themselves. So recently, there's some stats by Cisco which found that 50 percent of people see the value in IOT, only ten percent of them actually think their data is secure. The 42 percent would continue using the products anyway. And it's what's called in the research a ‘privacy paradox’ people value their privacy, but they don't readily take any action to protect it. And there's a number of reasons for this called ‘The Mirai’ botnet which was essentially hundreds and hundreds of thousands of exploited IOT devices that took down Netflix and Twitter and disrupted service access to these to these products.

Kim Mills: So it's not really happening to consumers so much at this point. They're targeting major corporations from what you're seeing.

John Blythe: Mainly being used in what we would call a ‘strategic risk’ where they're being used to take down a company or a service provider. We haven't seen many attacks against consumers themselves.

Kim Mills: What should consumers be worried about? I mean, I'm just imagining, and I've said this before to my friends and colleagues “You know you had a smart TV, you watch it, it watches you back.” What's it doing with this?

John Blythe: So, the Smart TV example was announced, actually, it was revealed that governments could potentially take sensitive data from the microphones in your Smart TVs, which could reveal quite private conversations that you have among family members. So there's that aspect to it the privacy side of your life. But also, like I said earlier, the safety side as well. If it's a children's toy, that's kind of the Internet in which a predator can potentially talk to your child. You know, that's very concerning.

Kim Mills: Well, it sounds like there are implications for law enforcement—you know where they might start asking if they can get records from these corporations. You know, say you're suspected of some kind of a crime. I mean is this what consumers should be thinking about right now as they're purchasing these items?

John Blythe: Yeah, and that has happened. There is an example of this in America where they have used data from a guy's Fitbit to show that he committed the murder of his wife.

Kim Mills: It's scary stuff.

John Blythe: Yeah.

Kim Mills: Are there particular devices that we should be leery about? And I'm thinking we want one device that's out there right now that kind of gives me the creeps is…Amazon is distributing this lock system that you can supposedly watch the delivery person arrive at your house. But basically, that person can go in your house to leave a package. Is that the kind of thing we should be concerned about?

John Blythe: Yes, I think there's the concerns in terms of: What if kind of device? Is it linked to something that’s safety critical? For example, your front door? Or is it linked to something that maybe has a heating element such as your boiler? Or something that’s security-related such as your security cameras? I think people should be concerned about potentially what is the device is linked to, and what might it reveal about your house, your occupancy, for example, smart thermostats can let somebody know whether you're in the house or not and that can be used to facilitate burglaries and other crimes as well.

Kim Mills: What are the next steps for you in terms of the research that you're doing?

John Blythe: So we're looking to work with the UK government to develop a labeling scheme. It's going to be called “Designed With Forth Experts and Consumers” because we need… so the consumer side of it is working with consumers to understand their preferences around what they want communicated on a label. What value do they see in a labeling scheme? Would it actually influence their behavior? But also work with my experts to actually identify the underpinning and technical content of the label because we're assessing objectively what security means so all of our workers a lot more on the technical side of that. We'll also run a series of experimental studies to look at the design aspects of the label and whether that nurtures people's behavior and whether it would actually lead to them purchasing a more secure product. Because ultimately, we want the label to act as a market leader and as a market differentiator so that people would be imaged to find a more secure and private device than one that isn’t.

Kim Mills: But your work is focused on the UK, right?

John Blythe: Yes.

Kim Mills: So again, as far as the United States, are we doing anything similar here?

John Blythe: So the UK government is in talks in collaboration with the USA because recognizing that actually these products are built across a global supply chain. They're not made primarily in the UK. They’re made across the world, so it's very important that governments do collaborate. The UK government is looking at consumer IOT and have released reports on this.

Kim Mills: What Internet of Things products do you have in your home?

John Blythe: I don't own any.

Kim Mills: You would know.

John Blythe: Yeah, I don't want to scare people into not buy these products, but there is some huge potential crime risk associated with these devices. And particularly, I mean the major manufacturers like Apple and Amazon, they do take security seriously. So if you're going to buy an IOT device, maybe go for one of the bigger providers rather than a cheaper one by a manufacturer who don't have the commoncy to understand security and bake it in the product.

Kim Mills: Given what's happened recently with Facebook, for example, can we trust these manufacturers? I mean, that's one of the biggest corporations in the world and yet yeah, you know their data. Who knows where it went?

John Blythe: Yeah, I don't want to say don't trust these companies. I think what needs to happen is that there needs to be a better way for people to understand what's happening with our data and not to rely on people to read terms and conditions because it's just impossible to expect people to read that. People just tic the box and then they move on, so how people are ever going to really be able to protect themselves—protect their personal information if we're relying on people to read those terms and conditions? In the UK, in the EU, we have the upcoming GDPR legislation, which is a really good piece of legislation. It’s going to put more power back to consumers around how their personal data is used and hopefully that will start the attraction towards privacy being taken more seriously as we are more internet connected.

Kim Mills: Anything else you'd like the public to know about the work that you're doing?

John Blythe: Ultimately, we want the label scheme because governments aren't regulating enough things, they're not enforcing manufacturers to actually ship these products with security built in. The UK government has said they are giving manufactures the opportunity to address this at the court of practice in the UK government, and if they aren't going to address it then they might they might look to a regulation for some manufacturers to do it. But in the absence of that, we need for example, the labeling scheme to actually help people make a distinction between a secure and insecure product. Otherwise there's no way for people to actually make that product choice, unless they’re gonna go out and research the security of the product which the average consumer probably won't do.

Kim Mills: Alright. Well, you've given us a lot to think about.

John Blythe: Yeah.

Kim Mills: Thank you very much for joining us today doctor.

John Blythe: Thank you.

Kim Mills: Speaking of Psychology is part of the APA podcast network, which includes other great podcasts such as APA Journals Dialogue, about the latest and most exciting psychological research, and Progress Notes, which discusses the practice of psychology. You can find all APA podcasts on iTunes, Stitcher or wherever you get your podcasts. You can also go to our website, www.speakingofpsychology.org, to listen to more episodes and see more resources on the topics we discuss. I'm Kim Mills, with the American Psychological Association, and this is Speaking of Psychology.

Date created: 2018

Speaking of Psychology

This audio podcast series highlights some of the latest, most important, and relevant psychological research being conducted today.

Produced by the American Psychological Association, these podcasts will help listeners apply the science of psychology to their everyday lives.

Your host: Kim I. Mills

Kim I. Mills created Speaking of Psychology in 2013 and took over as host in 2020. She is the former senior director of strategic external communications and public affairs for the American Psychological Association and spent 14 years as a reporter and editor for The Associated Press. Mills has also written for publications including The Washington Post, Fast Company, American Journalism Review, Dallas Morning News, and Harvard Business Review.